PT-2025-26179 · Ibm · Webmethods Integration Server
Filip Dragovic
·
Published
2025-06-18
·
Updated
2025-08-13
·
CVE-2025-36049
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM webMethods Integration Server versions 10.5, 10.7, 10.11, and 10.15
Description
The issue is related to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this to execute arbitrary commands.
Recommendations
For IBM webMethods Integration Server versions 10.5, 10.7, 10.11, and 10.15, consider disabling XML external entity processing until a patch is available.
Restrict access to XML data processing modules to minimize the risk of exploitation.
Avoid using vulnerable XML parsing functions until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webmethods Integration Server